The MySQL database is the most popular database in the open source world, because of ease of use, performance and high reliability. MySQL installation and configuration is very simple. Many of the world’s largest organizations rely on MySQL to save time and money power of their sites at high-volume and software.
This how-to will explain how to install mysql on linux, services status, secure post-install activities of MySQL, installation verification and how to connect with MySQL.
The install itself is one command. The part that actually matters is what you do in the ten minutes afterwards, because a default MySQL install ships with an anonymous account, a sample database anyone can reach, and no root password at all. Plenty of servers have been left exactly like that.
Installing MySQL Service
[root@linuxpathfinder ~]# yum install mysql-server mysql-client
Two packages doing different jobs. The server is the daemon that holds your data. The client is the command-line tool you connect with, and it is the only one you need on a machine that talks to a database living somewhere else. Application servers frequently need the client alone.
MySQL-devel – Libraries and header files
[root@linuxpathfinder ~]# yum install mysql-devel
Only needed if something is going to compile against MySQL, which in practice means language bindings being built from source. If you are just running a database, skip it.
Starting mysql services
[root@linuxpathfinder ~]# /etc/init.d/mysqld status
mysqld is stopped
[root@linuxpathfinder ~]# /etc/init.d/mysqld start
PLEASE REMEMBER TO SET A PASSWORD FOR THE MySQL root USER !
To do so, start the server, then issue the following commands:
/usr/bin/mysqladmin -u root password 'new-password'
/usr/bin/mysqladmin -u root -h linuxpathfinder password 'new-password'
Alternatively you can run:
/usr/bin/mysql_secure_installation
which will also give you the option of removing the test
databases and anonymous user created by default. This is
strongly recommended for production servers.
See the manual for more instructions.
You can start the MySQL daemon with:
cd /usr ; /usr/bin/mysqld_safe &
You can test the MySQL daemon with mysql-test-run.pl
cd /usr/mysql-test ; perl mysql-test-run.pl
Please report any problems with the /usr/bin/mysqlbug script!
Starting mysqld: [ OK ]
Read that banner rather than scrolling past it. MySQL is telling you outright that root currently has no password, which means anyone who can reach the port is already an administrator. It is the single most useful thing the installer prints and it is the thing people most often skip.
Note that starting the service and enabling it at boot are separate actions. A database that comes up fine now and vanishes after the next reboot is almost always one that was started but never enabled.
Secure post-install Activities on MySQL
[root@linuxpathfinder ~]# /usr/bin/mysqladmin -u root password 'mypassword'
mysql_secure_installation script is the best option to run because of typical security related items on the MySQL as shown below. It does on a high level items as follows:
- Change the root password
- Remove the anonymous user
- Disallow root login from remote machines
- Remove the default sample test database
Those four are worth taking individually, because the script asks about each one and it helps to know what you are agreeing to.
The root password closes the obvious hole. The anonymous user is the surprising one: a default install includes an account with no username that can connect and see the test database, which exists so the installation can be verified and has no business surviving past that. Disallowing remote root means an attacker who finds your port cannot sit there guessing the root password from another machine. And the test database is a share-with-everyone scratch space nobody needs.
Answer yes to all four. There is no realistic production setup where any of them should stay.
[root@linuxpathfinder ~]# mysql_secure_installation
NOTE: RUNNING ALL PARTS OF THIS SCRIPT IS RECOMMENDED FOR ALL MySQL
SERVERS IN PRODUCTION USE! PLEASE READ EACH STEP CAREFULLY!
In order to log into MySQL to secure it, we'll need the current
password for the root user. If you've just installed MySQL, and
you haven't set the root password yet, the password will be blank,
so you should just press enter here.
Enter current password for root (enter for none):
OK, successfully used password, moving on...
Setting the root password ensures that nobody can log into the MySQL
root user without the proper authorisation.
You already have a root password set, so you can safely answer 'n'.
Change the root password? [Y/n] Y
New password:
Re-enter new password:
Password updated successfully!
Reloading privilege tables..
... Success!
By default, a MySQL installation has an anonymous user, allowing anyone
to log into MySQL without having to have a user account created for
them. This is intended only for testing, and to make the installation
go a bit smoother. You should remove them before moving into a
production environment.
Remove anonymous users? [Y/n] Y
... Success!
Normally, root should only be allowed to connect from 'localhost'. This
ensures that someone cannot guess at the root password from the network.
Disallow root login remotely? [Y/n] Y
... Success!
By default, MySQL comes with a database named 'test' that anyone can
access. This is also intended only for testing, and should be removed
before moving into a production environment.
Remove test database and access to it? [Y/n] Y
- Dropping test database...
... Success!
- Removing privileges on test database...
... Success!
Reloading the privilege tables will ensure that all changes made so far
will take effect immediately.
Reload privilege tables now? [Y/n] Y
... Success!
Cleaning up...
All done! If you've completed all of the above steps, your MySQL
installation should now be secure.
Thanks for using MySQL!
Two minutes of prompts, and it closes every default weakness the install shipped with. Run it on every new MySQL server, without exception.
Verify Installation:
[root@linuxpathfinder ~]# mysql -V
mysql Ver 14.14 Distrib 5.1.69, for redhat-linux-gnu (i386) using readline 5.1
Distrib 5.1.69 is the number that matters. The 14.14 is the client protocol version and it stays put across releases, which confuses people who read it as the MySQL version.
Login into MySQL Prompt:
Enter this command and you will be prompted to enter the password for the MySQL user
[root@linuxpathfinder ~]# mysql -u root -p
Enter password:
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 15
Server version: 5.1.69 Source distribution
Copyright (c) 2000, 2013, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its
affiliates. Other names may be trademarks of their respective
owners.
Type 'help;' or '\h' for help. Type '\c' to clear the current input statement.
mysql>
Using -p on its own and letting MySQL prompt is the right habit. Attaching the password to the flag directly works too, but it lands in your shell history and shows up in the process list while the command runs.
MySQL Status
To know the status, enable and disable the MySQL service.
[root@linuxpathfinder ~]# /etc/init.d/mysqld status
mysqld (pid 13708) is running...
[root@linuxpathfinder ~]# /etc/init.d/mysqld stop
Stopping mysqld: [ OK ]
[root@linuxpathfinder ~]# /etc/init.d/mysqld start
Starting mysqld: [ OK ]
[root@linuxpathfinder ~]# /etc/init.d/mysqld restart
Stopping mysqld: [ OK ]
Starting mysqld: [ OK ]
[root@linuxpathfinder ~]# service mysqld status
mysqld (pid 14169) is running...
[root@linuxpathfinder ~]# service mysqld stop
Stopping mysqld: [ OK ]
[root@linuxpathfinder ~]# service mysqld start
Starting mysqld: [ OK ]
Both forms shown there do the same thing. Calling the init script directly runs it, while service is a wrapper that finds the script and runs it in a cleaner environment. The wrapper is the better habit of the two.
Installation of mysql in linux guide is finished here. Hope this guide will be invaluable for you.
One note on the vintage of all this, since the output above says so plainly: this was done on MySQL 5.1 with SysV init scripts. Systems using systemd manage the service through systemctl instead, and on Red Hat family releases from 7 onwards the default database package became MariaDB rather than MySQL, so the package and service names differ there. The security steps are unchanged. Whatever the packaging, a fresh install still starts with no root password, an anonymous user and a test database, and mysql_secure_installation is still how you deal with all three.
Once the server is up and secured, the next two jobs are usually setting the administrator password and creating an account for your application. Both are covered separately in changing the MySQL root password and creating a MySQL user with scoped permissions.
